SOOSH is committed to protecting your privacy as an online visitor to our website.

This Privacy Policy provides you with details of how SOOSH collects and processes your personal data through your use of our website: www.bysoosh.com.au.

We aim to comply with the Australian Privacy Principles contained in the Privacy Act 1988 (Cth) and, where applicable, the General Data Protection Regulation (GDPR), to ensure that your information is protected.

We use the information we collect about you to provide and improve our services and products.

By providing us with your data, you confirm that you are over the age of 18 years.

This Privacy Policy, together with our Website Terms and Conditions (including Disclaimer) and Listing Terms and Conditions, form the entire agreement between you and SOOSH.

SOOSH is the controller of the personal information collected via this website; therefore, we are responsible for your personal data (referred to as "we", "us", or "our" in this Privacy Policy).

1. Contact Details

Please email contact@bysoosh.com.au to request our postal address, as our business is operated from a private address.

1.1. It is important that the information we hold about you is accurate and up to date. Please let us know if your personal information changes by emailing contact@bysoosh.com.au.

2. Personal Information – Type, Purpose and Legal Grounds

2.1. Personal information/data means any information capable of identifying an individual. It does not include anonymous or de-identified data.

2.2. We may process the following categories of personal data about you:

2.2.1. Communication Information

2.2.1.1. This includes communications sent to us via:

  • Our website contact or subscriber forms
  • Email, SMS, or social media platforms
  • Any other method of direct communication

2.2.1.2. We process this data for:

  • Communicating with you
  • Keeping records
  • Managing or responding to legal claims

2.2.1.3. Legal basis: Our legitimate interests — to respond to communications, keep records, and protect our legal position.

2.2.2. Customer Information

2.2.2.1. This includes data relating to your purchases, such as name, contact details, billing and delivery addresses, and purchase/payment details.
2.2.2.2. We use this to:

  • Fulfil your order
  • Maintain transaction records

2.2.2.3. Legal basis: The performance of a contract between you and us, or steps taken at your request before entering into a contract.

2.2.3. User Information

2.2.3.1. Includes data about how you use our website and services, or any data you publish via our website. For example:

  • Service use patterns (frequency, duration)
  • Account information (name, email, DOB)
  • Feedback, support interactions, and surveys
  • Any other personal information you provide

2.2.3.2. If you provide us with another person’s personal information, you must first obtain their consent to disclose and for us to use it as set out in this policy.

2.2.3.3. We use this data to:

  • Operate our website
  • Secure and maintain our systems
  • Manage website content and user accounts

2.2.3.4. Legal basis: Legitimate interests — to operate our platform effectively and securely.

2.2.3.5. We will not share your personal information with any third party for direct marketing purposes without your express consent.

2.2.4. Technical Data

2.2.4.1. This includes data collected automatically, such as IP address, browser type, device information, referral source, pages viewed, and usage patterns.
2.2.4.2. We collect this via analytics and tracking tools.
2.2.4.3. Used to improve website functionality, monitor traffic, and understand user behaviour.
2.2.4.4. Legal basis: Legitimate interests — to optimise website performance and marketing strategy.

2.2.5. Financial Transactions

2.2.5.1. We use third-party payment processors to manage transactions on our website.
2.2.5.2. We only share information necessary to process payments, issue refunds, or handle disputes.
2.2.5.3. Your payment details are not stored by us.
2.2.5.4. Personal data may be shared with suppliers only where legally required or to protect our legal rights (e.g., trademarks, copyright).

2.2.6. Marketing Information

2.2.6.1. Includes your marketing preferences and communication choices.
2.2.6.2. Used to:

  • Send newsletters or promotional content
  • Conduct giveaways or competitions
  • Analyse the effectiveness of campaigns

2.2.6.3. Legal basis: Legitimate interests — to grow our business and improve services.
2.2.6.4. We may use a combination of customer, user, technical and marketing data for advertising purposes, including:

  • Delivering personalised ads (e.g., Facebook or Google Ads)
  • Measuring ad performance

2.2.6.5. Legal basis: Consent or legitimate interest — to promote business growth.
2.2.6.6. We will obtain your express consent where legally required.

2.2.7. Sensitive Data

We do not collect sensitive personal data, including:

  • Health, racial or ethnic origin, religious beliefs, political opinions, or criminal records
    Please do not submit this type of data unless requested for a lawful purpose.

2.2.8. Contract Obligations

2.2.8.1. Where required by law or our contract, failure to provide requested personal data may mean we are unable to supply you with goods or services.
2.2.8.2. If that occurs, we will notify you.

2.2.9. Use of Personal Information

2.2.9.1. We only use your data for the purpose for which it was collected or for a reasonably related purpose.
2.2.9.2. We may process your information without your consent where legally required or permitted.

3. How Your Personal Information Is Collected

3.1. Cookies

3.1.1. We collect data using cookies and similar tracking technologies.
3.1.2. Cookies are small data files that help websites remember your preferences and usage behaviour.
3.1.3. They are safe and widely used.
3.1.4. You can control cookie settings via your browser. Blocking cookies may affect some features.

3.2. How Do We Use Cookies?

3.2.1. To understand how visitors use our site and improve your experience.

3.3. Types of Cookies

3.3.1. Session cookies — temporary, deleted when you close your browser
3.3.2. Persistent cookies — stored on your device, e.g., Google Analytics

3.4. Cookie Categories

3.4.1. Strictly necessary — essential for core functionality
3.4.2. Performance — analyse website usage
3.4.3. Functionality — remember your settings or preferences
3.4.4. Third parties (e.g., ad networks) may also use cookies, which we do not control.

4. Marketing Communications

4.1. Our legal basis is your consent or our legitimate interests to grow our business.

4.2. We may send you marketing communications if:
4.2.1. You purchased from us or asked for information
4.2.2. You opted in to receive emails
4.2.3. You are a business contact, and we have inferred consent (you can opt out at any time)

4.3. We will seek express consent before sharing your data with third parties for their own marketing.

4.4. To stop marketing messages:

  • Use the unsubscribe link in emails
  • Email us at contact@bysoosh.com.au

4.4.2. Opting out won’t affect communications about past transactions or support.

5. Disclosures of Your Personal Data

5.1. We may share your data with:

  • IT and admin service providers
  • Professional advisers
  • Government authorities (as required by law)
  • Market researchers or marketing partners
  • Third parties in the event of a business sale or merger

5.2. We ensure that third parties treat your data confidentially and in compliance with applicable laws.

6. International Transfers

6.1. If we transfer your data outside Australia (e.g., to a cloud provider or CRM system), we ensure:
6.1.1. The destination country has adequate legal protections; or
6.1.2. We use safeguards such as Standard Contractual Clauses; or
6.1.3. Where required, we request your explicit consent.

6.2. You may withdraw your consent at any time.

7. Data Security

7.1. We take reasonable steps to protect your information from loss, misuse or unauthorised access.
7.2. However, the internet is not 100% secure, and we cannot guarantee the security of your data during transmission.
7.3. We have systems in place to respond to suspected data breaches and will notify you where required.

8. Data Retention

8.1. We retain your data only for as long as necessary to meet the purpose for which it was collected.
8.2. We are required to retain some customer data (e.g., financial records) for five years for tax and compliance purposes.
8.3. We may de-identify data for research or statistical use, which we may retain indefinitely.

9. Your Legal Rights

9.1. You have the right to:

  • Access or correct your personal data
  • Request erasure or restriction
  • Object to processing
  • Data portability
  • Withdraw consent

9.2. To exercise your rights, please email contact@bysoosh.com.au

9.3. We may require your name, address, and contact details to verify your identity.

9.4. No fee will apply unless your request is manifestly unfounded or excessive.

9.5. We may request further information for security reasons.

9.6. We aim to respond within 30 days. You will be notified if more time is required.

9.7. If you are unhappy with how we handle your data, you can complain to the Office of the Australian Information Commissioner at www.oaic.gov.au

10. Change in Privacy Policy

10.1. This policy is subject to change.
10.2. Any updates will be posted on this website and will take effect immediately.
10.3. You may instruct us not to use your information for marketing purposes at any time.
10.4. We will generally ask for your consent in advance or offer a clear opt-out.
10.5. For any questions, please contact contact@bysoosh.com.au